Junglewise Threat Intelligence

CVE-2026-42098: Sparx Enterprise Architect client-side authentication bypass

CVE-2026-42098 · Severity: info · CVSS 8.7 · Published 2026-05-19

Vendors: Sparx Systems.

Executive brief

Sparx Enterprise Architect, a visual modeling and design tool, contains a security flaw that allows users to bypass their assigned permissions. By manipulating the software's client-side behavior, an authenticated user can impersonate any other user, including administrators. This allows an attacker to gain full control over the project repository, potentially leading to the unauthorized modification or deletion of critical business designs and intellectual property.

Technical details

Sparx Enterprise Architect (up to version 17.1) suffers from a 'Use of Client-Side Authentication' vulnerability (CWE-603). The software relies on the client application to enforce user role restrictions rather than server-side validation. An authenticated attacker can use a debugger or other memory manipulation tools to modify the client's execution flow, allowing them to log in as any other user or administrator. Once impersonation is successful, the attacker gains full read/write access to the repository. As of the advisory date, the vendor has not provided a patch or specific version range for a fix.

Affected products

  • Sparx Systems Enterprise Architect All versions through 17.1

Timeline

  • 2026-05-19: disclosed: Vulnerability disclosed by CERT Polska
  • 2026-05-19: advisory: NVD record published

References